Agent skill

Commerce App API Mesh

by adobe in adobe/skills

Scaffold or update an Adobe API Mesh configuration (mesh.json) in front of a Commerce app: add GraphQL/OpenAPI sources, extend an existing Commerce GraphQL type with a new field, and wire a…

Apache-2.0Auto-check passedBackend & APIs

Install Commerce App API Mesh

skills CLI
$ npx skills add adobe/skills --skill commerce-app-api-mesh -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install adobe/skills commerce-app-api-mesh --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/adobe/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/commerce/app-management/skills/commerce-app-api-mesh .claude/skills/commerce-app-api-mesh && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
commerce-app-api-mesh
GitHub stars
195
Token cost
~2.3k tokens
SKILL.md length
917 words
Files
1
Skills in repo
105
Repo updated
First seen
Licence
Apache-2.0

At a glance

Scaffold or update an Adobe API Mesh configuration (mesh.json) in front of a Commerce app: add GraphQL/OpenAPI sources, extend an existing Commerce GraphQL type with a new field, and wire a…

  • Works in 4 steps: Confirm schema shapes via introspection → Scaffold sources → Extend a type and wire the resolver → …
  • The user mentions API Mesh
  • SKILL.md covers Prerequisites, Step 1 — Confirm schema shapes…, Step 2 — Scaffold sources and Step 3 — Extend a type and…, plus 5 more sections
  • Calls curl

What it does

Commerce App API Mesh is an agent skill from adobe/skills. Scaffold or update an Adobe API Mesh configuration (mesh.json) in front of a Commerce app: add GraphQL/OpenAPI sources, extend an existing Commerce GraphQL type with a new field, and wire a cross-source resolver for it. Use when the user mentions API Mesh, mesh.json, extending a Commerce GraphQL type (e.g. adding a field to Order/CustomerOrder/Product), or stitching a runtime action's data into the storefront's GraphQL schema.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires the api-mesh CLI plugin (aio plugins install @adobe/aio-cli-plugin-api-mesh). If wrapping a runtime action as a source, that action must already be…

It sits in Backend & APIs, covering GraphQL. It works with GraphQL and OpenAPI. The repository describes itself as: Adobe Skills for Agents. The licence is Apache-2.0.

When your agent uses it

  • The user mentions API Mesh
  • Extending a Commerce GraphQL type (e.g

Example prompts

  • “s data into the storefront”
  • “/commerce-app-api-mesh”

Requirements

  • Compatibility (from SKILL.md): Requires the api-mesh CLI plugin (aio plugins install @adobe/aio-cli-plugin-api-mesh). If wrapping a runtime action as a source, that action must already be built and deployed.

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Confirm schema shapes via introspection
  2. Scaffold sources
  3. Extend a type and wire the resolver
  4. Deploy and verify

What it can do on your machine

Read from SKILL.md and the folder at commit cbc9952. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • developer.adobe.com
    • raw.githubusercontent.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires the api-mesh CLI plugin (aio plugins install @adobe/aio-cli-plugin-api-mesh). If wrapping a runtime action as a source, that action must already be built and deployed.

    From compatibility in the SKILL.md frontmatter.

Context cost

Commerce App API Mesh loads about 2.3k tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 917 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from adobe/skills at commit cbc9952, republished under its Apache-2.0 licence (© adobe). 917 words, ~2,287 tokens.

Download SKILL.mdSave it as .claude/skills/commerce-app-api-mesh/SKILL.md (or your agent's skills folder).
name
commerce-app-api-mesh
description
Scaffold or update an Adobe API Mesh configuration (mesh.json) in front of a Commerce app: add GraphQL/OpenAPI sources, extend an existing Commerce GraphQL type with a new field, and wire a cross-source resolver for it. Use when the user mentions API Mesh, mesh.json, extending a Commerce GraphQL type (e.g. adding a field to Order/CustomerOrder/Product), or stitching a runtime action's data into the storefront's GraphQL schema.
compatibility
Requires the api-mesh CLI plugin (aio plugins install @adobe/aio-cli-plugin-api-mesh). If wrapping a runtime action as a source, that action must already be built and deployed.
license
Apache-2.0
metadata.author
adobe

Wire API Mesh in Front of a Commerce App

Composes Commerce's own GraphQL API and this app's runtime actions into a single mesh schema. Two moves this skill covers: exposing a runtime action as a mesh source, and extending an existing Commerce type with a field resolved by delegating to that source.

This skill assumes general API Mesh knowledge (mesh.json anatomy, handler types, transforms, hooks, secrets, CORS, generic declarative/programmatic resolvers). If any of that is unfamiliar, load it from Adobe's own material first — see References — rather than guessing at syntax. None of that material covers extending an existing Commerce type via additionalResolvers (targetTypeName/sourceTypeName/requiredSelectionSet/sourceSelectionSet) or wrapping an aio-commerce-sdk runtime action as a mesh source — that's what follows.

Prerequisites

  • aio plugins install @adobe/aio-cli-plugin-api-mesh is installed.
  • If exposing a runtime action as a source, it's already built and deployed with a real, reachable HTTPS endpoint — a source pointing at an undeployed action fails opaquely.
  • Check whether a mesh already exists for this workspace: aio api-mesh:get. "No mesh found" → you'll create; otherwise you're editing an existing mesh.json and will update.

Step 1 — Confirm schema shapes via introspection

Before writing additionalTypeDefs or additionalResolvers, introspect the Commerce (or other) GraphQL source you're extending. Don't assume a type/field name from memory or a similar-sounding convention — near-miss names produce a mesh that builds successfully but whose resolver never fires.

bash
curl -s -X POST "<graphql-endpoint>" -H "Content-Type: application/json" \
  -d '{"query":"{ __type(name: \"<TargetType>\") { fields { name } } }"}'

Step 2 — Scaffold sources

json
{
  "name": "Commerce",
  "handler": {
    "graphql": {
      "endpoint": "<commerce-graphql-endpoint>",
      "operationHeaders": { "Authorization": "{context.headers.authorization}" }
    }
  }
}

Include operationHeaders by default on any source whose schema has customer-, cart-, or session-scoped fields — API Mesh does not forward the caller's Authorization header automatically. Omitting it makes every authenticated query fail with the backend's own generic "not authorized" error, indistinguishable from an invalid token.

To wrap a runtime action, write a small static OpenAPI document describing just its endpoint and reference it by relative path:

json
{
  "name": "<SourceName>",
  "handler": { "openapi": { "source": "./mesh/<source>.json" } }
}

The OpenAPI document itself needs enough shape for the mesh to generate a Query field from it — not just the pointer above. Minimal example for a single-endpoint runtime action:

json
{
  "openapi": "3.0.0",
  "info": { "title": "<SourceName>", "version": "1.0.0" },
  "servers": [{ "url": "<runtime-action-base-url>" }],
  "paths": {
    "/<action-path>": {
      "get": {
        "operationId": "<sourceField>",
        "parameters": [
          {
            "name": "<arg>",
            "in": "query",
            "required": true,
            "schema": { "type": "string" }
          }
        ],
        "responses": {
          "200": {
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": { "<resultField>": { "type": "string" } }
                }
              }
            }
          }
        }
      }
    }
  }
}

operationId becomes the Query field name — it must match sourceFieldName in Step 3's resolver exactly, or the resolver builds successfully but never fires.

The declared response schema must match what the action actually returns — the mesh parses according to what you declare, it doesn't reshape data.

Step 3 — Extend a type and wire the resolver

json
"additionalTypeDefs": "extend type <TargetType> { <newField>: String }",
"additionalResolvers": [
  {
    "targetTypeName": "<TargetType>",
    "targetFieldName": "<newField>",
    "sourceName": "<SourceName>",
    "sourceTypeName": "Query",
    "sourceFieldName": "<sourceField>",
    "requiredSelectionSet": "{ <keyField> }",
    "sourceArgs": { "<arg>": "{root.<keyField>}" },
    "sourceSelectionSet": "{ <resultField> }",
    "result": "<resultField>"
  }
]

Always pair sourceSelectionSet with result when extracting a scalar from an object-returning source field — never use result alone. The result-only path builds its selection set by hand instead of via the GraphQL parser, and breaks with "No type was found for field node ... __typename" specifically when the target field resolves inside a list (e.g. a parent's items[].<newField>). A direct root-query call to the same source field succeeds even when this bug is present, so that test alone isn't sufficient proof the resolver works.

Show full SKILL.md (459 more words)Show less

Step 4 — Deploy and verify

If you already know a browser-based app will call this mesh, decide responseConfig.CORS now, before your first deploy — the browser-verification tier below exists to catch a missed CORS config, but deciding upfront avoids a second deploy cycle.

The first aio api-mesh:* call in a session opens an interactive browser login (Waiting for browser login...). An agent without browser access can't complete this itself — hand the printed login URI to the human and wait.

sh
aio api-mesh:create mesh.json -c   # first time
aio api-mesh:update mesh.json -c   # subsequent edits

-c/--autoConfirmAction skips the interactive Are you sure you want to update the mesh: <id>? prompt. That prompt is the only checkpoint before mutating a mesh other people or systems may already depend on — reserve -c for a workspace-scoped mesh you just created yourself (e.g. in CI, or a throwaway dev workspace). When updating an existing, shared, or already-deployed mesh, omit -c and have a human confirm the prompt, or at minimum get explicit human sign-off on the diff before running the command — treat this like any other live-infrastructure change, not a routine CLI call.

Provisioning is asynchronous — poll rather than assume completion:

sh
until aio api-mesh:status 2>&1 | grep -qi success; do sleep 20; done

Verify in two tiers: first the source's root field directly, then the field in its real nested/authenticated shape (a list-nested query with a real caller credential, not a flat root-field call). Tier 1 passing does not prove tier 2 works — the bug above is invisible in tier 1.

If the consuming app will call this mesh directly from a browser (not just server-to-server), add a third tier: a real request from that app's actual origin. The two tiers above only prove server-side reachability — a mesh with no responseConfig.CORS entry for that origin passes both while still failing every browser call through it, not just the new field (see the CORS section of the api-mesh-starter-kit reference below).

Common Issues

  • "not authorized" on an authenticated query, even with a valid token — the source's graphql handler is missing operationHeaders. Check mesh.json, not the token.
  • "No type was found for field node ... __typename" on a nested/list field, but the source works fine at root — the resolver uses result without sourceSelectionSet. Add it.

Quality Bar

  • aio api-mesh:status reports success, and the new field resolves correctly in its real nested/authenticated shape, not just at the source's root field.
  • If a browser-based app will call this mesh, that app can complete a real request against it — not just aio api-mesh:status and curl.

Chaining

  • The source doesn't exist yet as a runtime action — invoke commerce-app-storage, commerce-app-webhooks, or commerce-app-eventing to scaffold and deploy it first.

References

  • API Mesh prompting guide — Adobe's own guidance for prompting an agent to write mesh configs; general workflow and expectations
  • api-mesh-starter-kit llm.txt — reference knowledge base covering mesh.json anatomy, all three handler types, transforms, hooks, secrets, context state, CORS, and the CLI command set

© adobe, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/commerce/app-management/skills/commerce-app-api-mesh of adobe/skills.

Open the folder on GitHubat commit cbc9952

Compare with similar skills

Commerce App API Mesh next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Commerce App API Mesh compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Commerce App API Mesh this skilladobe/skills195—~2.3kAutomated safety check: PassApache-2.0
API DesignerJeffallan/claude-skills12k2 repos~2kAutomated safety check: PassMIT
Designing APIsCloudAI-X/claude-workflow-v21.4k2 repos~1.2kAutomated safety check: PassMIT
SpikardGoldziher/spikard123—~799Automated safety check: PassMIT
Executor Usagejeremyosih/pi-executor104—~1.4kAutomated safety check: PassMIT
AurlShawnPana/aurl167—~536Automated safety check: PassMIT

Similar skills

  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 2 repos~2k tokens
    Backend & APIsAuto-check passed
  • Designing APIs

    CloudAI-X/claude-workflow-v2

    Designs REST and GraphQL APIs including endpoints, error handling, versioning, and documentation.

    1.4k GitHub starsUsed in 2 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Spikard

    Goldziher/spikard

    Scaffold Spikard projects and generate code from OpenAPI, AsyncAPI, OpenRPC, GraphQL, and Protobuf schemas using the Spikard CLI or its MCP server.

    123 GitHub stars~799 tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Executor Usage

    jeremyosih/pi-executor

    Load this skill before using the execute tool. An agent skill from jeremyosih/pi-executor.

    104 GitHub stars~1.4k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Aurl

    ShawnPana/aurl

    Turn any API into a CLI command. An agent skill from ShawnPana/aurl.

    167 GitHub stars~536 tokensUpdated 6 mo ago
    Backend & APIsAuto-check passed
  • Distilled SDK

    alchemy-run/distilled

    Build or update a distilled SDK for an API provider — sourcing its OpenAPI/Smithy/GraphQL/discovery description, adding the spec mirror that feeds it, generating packages/<provider, listing it on…

    431 GitHub stars~6k tokensUpdated today
    Backend & APIsAuto-check passed

More from adobe/skills

All 105 skills in this repo
  • Scaffolds, implements, deploys and debugs Adobe Runtime actions in App Builder projects, with templates for webhooks, events, database CRUD, sequences and Asset Compute workers.

    195 GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Launches Chrome with an unpacked extension over CDP, opens its sidepanel, popup or options page, and hands over to cdp-connect for clicks, typing and screenshots.

    195 GitHub stars~952 tokensUpdated today
    Auto-check passed
  • Extracts icons, metadata, text, forms, videos and social links from any web page with playwright-cli, with SVG icon classification and cleanup.

    195 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Page Langs

    adobe/skills

    Detect all languages used on a webpage — both declared (html@lang, hreflang alternate links, nested lang= attributes, meta content-language) and actually present in the body text (Google CLD3 via…

    195 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Page Prep

    adobe/skills

    Prepare any webpage for clean interaction by detecting and removing disruptive overlays (cookie banners, GDPR consent, modals, popups, newsletter signups, paywalls, login walls).

    195 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Page Reduce

    adobe/skills

    Reduce a webpage to a structural skeleton with semantic tokens.

    195 GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Commerce App API Mesh

What does Commerce App API Mesh do?

Scaffold or update an Adobe API Mesh configuration (mesh.json) in front of a Commerce app: add GraphQL/OpenAPI sources, extend an existing Commerce GraphQL type with a new field, and wire a…. Commerce App API Mesh is an agent skill from adobe/skills.json) in front of a Commerce app: add GraphQL/OpenAPI sources, extend an existing Commerce GraphQL type with a new field, and wire a cross-source resolver for it.

When should I use Commerce App API Mesh?

Commerce App API Mesh fits situations like: the user mentions API Mesh; extending a Commerce GraphQL type (e.g.

How do I install Commerce App API Mesh in Claude Code?

Run `npx skills add adobe/skills --skill commerce-app-api-mesh -a claude-code`. Or copy the skill folder (plugins/commerce/app-management/skills/commerce-app-api-mesh in adobe/skills) into .claude/skills/commerce-app-api-mesh in your project. Claude Code loads it when a task matches its description.

How do I install Commerce App API Mesh in Codex?

Run `npx skills add adobe/skills --skill commerce-app-api-mesh -a codex`. Or copy the skill folder (plugins/commerce/app-management/skills/commerce-app-api-mesh in adobe/skills) into .agents/skills/commerce-app-api-mesh in your project. Codex loads it when a task matches its description.

Can I use Commerce App API Mesh in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add adobe/skills --skill commerce-app-api-mesh -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/commerce-app-api-mesh, .gemini/skills/commerce-app-api-mesh, .github/skills/commerce-app-api-mesh and .opencode/skills/commerce-app-api-mesh in your project.

What does Commerce App API Mesh need to run?

Going by SKILL.md and its folder, Commerce App API Mesh needs the command-line tools its instructions call (curl). Compatibility (from SKILL.md): Requires the api-mesh CLI plugin (aio plugins install @adobe/aio-cli-plugin-api-mesh). If wrapping a runtime action as a source, that action must already be built and deployed. .

Does Commerce App API Mesh access the network?

SKILL.md names 2 domains. As links in the text: developer.adobe.com and raw.githubusercontent.com. This is read from the text; nothing was executed.

Is Commerce App API Mesh safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Commerce App API Mesh use?

Commerce App API Mesh is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Commerce App API Mesh use?

About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Commerce App API Mesh?

Skills that share tags, products or a category with Commerce App API Mesh: API Designer (Jeffallan/claude-skills, 12k stars), Designing APIs (CloudAI-X/claude-workflow-v2, 1.4k stars), Spikard (Goldziher/spikard, 123 stars) and Executor Usage (jeremyosih/pi-executor, 104 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Commerce App API Mesh?

adobe (a GitHub organization) maintains it in adobe/skills, which has 195 GitHub stars. The repository holds 105 skills in this directory. The repository was last updated on October 6, 2026.

Source: adobe/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.